Zero Trust for AI — Controlling 50 Million Agents in One Go
When every employee runs a hundred AI agents and every enterprise stack lights up with many-to-many traffic, perimeter security stops making sense. Duncan Greatwood, CEO of Xage Security, joins Alan Shimel on Techstrong TV to explain why the chaos Xage solved in oil pipelines, utilities, and military networks is the exact same chaos now showing up inside enterprise AI. Duncan walks through Xage’s Zero Trust for AI architecture — a two-stage approach that puts zero trust controls in front of every critical resource and wraps each agent in a local Sentry that watches and enforces actions on the box where it runs. He also breaks down the new NVIDIA partnership announced at GTC, where Xage’s controls are embedded deep in the NVIDIA stack to govern up to 50 million agents and 10 million simultaneous AI interactions in a single AI factory.
Transcript
Hey everyone, this is Alan Shimel, and welcome to another Techstrong TV interview. For this interview, I want to introduce you to Duncan Greenwood, who is the CEO for Xage. That's X-A-G-E.
Duncan, welcome to Techstrong TV. It's great to have you on. Thank you for having me.
And this is my third go around as a startup CEO. First one was a email security company. It did really well and was acquired by Cisco a few years back.
And then I had a chance to join a search and privacy company called Topsy Labs, that really did splendidly well and ended up getting acquired by Apple. And I got to work at Apple for a few years, doing a whole bunch of interesting projects there. It's one of the most fun places to work if you ever get the chance.
So many interesting things going on. But then I got excited by Xage and really a very new approach to cybersecurity that the founders here had, and so here I am doing Xage today. Excellent.
Let's talk Xage. Yeah. I'll be honest, I didn't know of the company until we put this interview on the books, and I'm sure many people in our audience haven't either.
So give us the scoop. Yeah. So you're not alone in not having heard of us.
I think we're one of those overnight successes that's taken five or six years to bring about. So we're very happy to be- As many do ... we're very happy to be in that state of inflection right now.
So we brought this new technical approach to cyber, which we call a fabric, and other people might call a mesh. We lay the fabric over the customer's systems to protect them, and we control all of the things that are going on in the customer's environment, the back and forths between things. And that's really a new kind of approach and it was one that found its first home in critical infrastructure.
So oil and gas pipelines, renewable energy, utilities, advanced manufacturing, a whole bunch of industrial and indeed military applications as well. And our first burst of acceleration really came after the Colonial Pipeline was hacked on the East Coast. I don't remember if Colonial goes down as far as Florida, but it's certainly along the East and- I remember the incident, right?
Yeah. So when that happened, it really alerted a whole bunch of critical infrastructure operators to the risks they were running, and they turned to Xage to help protect them and to bring a level of rigor into those environments that perhaps hadn't quite existed before in terms of determining who was allowed to do what and why. And we've continued to grow that business over the last several years.
Things have been going very well. We doubled our business last year, as I think we previously announced. What's happened this year is that the rate of growth has really accelerated to a whole new level.
And that's being driven by AI, unsurprisingly. Everybody's doing AI now. But what we realized a year or so ago was that a lot of the problems that we'd solved in critical infrastructure are recurring now in the AI environments.
Critical infrastructure is, there's industrial environments, they're a little bit chaotic. They have many things talking to many things. And IT didn't used to be like that.
You'd have your big application and people log into it, and it was hub and spoke, and you defend the big, important things, you were good. Once you let loose all of these agents all over the place, then suddenly you're back in a world of many things talking to many things, and you have to keep track of that and bring it under a measure of control. And so we've been busy building that capability for the AI environments.
We've already won some pretty exciting customers across US military. A bunch in advanced manufacturing and a bunch in the energy sector again as well. So, I'll give you an example of the kind of problem that we can solve where, if a human gives an instruction to an agent and the agent talks to another agent, maybe talks to an AI LLM, talks back to an agent, that's going to talk to a database.
By the time you get to the database, you have to ask the question: Well, is that user allowed to access this database? But they're six hops back in the whole system. So this is why the fabric is so powerful for AI, is because the fabric can watch all of those hops and trace all the way along, and certainly you want the user to have the necessary privileges.
You want to make sure that all of the agents as well are not abusing things as you go through that chain and finally get to where you want to go. So, we have some nice examples where we use AI to connect up to somebody's HR database, and people can read their own salary, but they can't read the salary of the person sitting next to them. The HR manager's allowed to give you a 10% pay rise, but not 100% pay rise.
And so on and so forth. So, what we're really bringing is that same level of rigor from critical infrastructure control and visibility as well, and not just knowing what the AI was asked to do, not just knowing what it said it did, but what did it really do? What were the real actions under the cover, whether that's writing a database or tweaking aA knob or whatever else it might be.
Really understanding the actions that were taken and placing those actions under control, and that's kind of a first in the AI environment. We believe it's a huge enabler of people applying AI to high-stakes problems. Not just the chitchat, the chatbot, but the stuff that really matters to them.
Well, but- Yeah ... it's funny. We're not a big company.
We're certainly not critical infrastructure. But my background is in security, and so we began an agentic AI experiment here three, four months ago. And as the CEO, I said, "Look, go experiment.
" Yeah. "But go experiment. The only thing I ask is tell me what you're doing, and is it working?
Is it not working? " And the other thing was, if you're using Claw or any of these, I made them put them on a Mac Mini running on a VMware on top of that and starting with very much a zero-trust- Mm-hmm. Yeah ...
profile. Yeah. And then turn on one thing at a time as needed- Yeah ...
and only for that thing. Yeah. But I've got 25 years, 30 years in security.
Mm-hmm. That was a natural thing for me. Yeah.
I don't think most organizations do, even in critical infrastructure, they don't realize that if you don't have that kind of zero-trust posture to begin with- Yeah ... it's trouble. So now, the other thing that scares me, though, is it was easy when it was just OpenClaw.
Now you've got NanoClaw, and then NVIDIA has their Claw, and then you've got Codex from OpenAI, and Claw coworker, and- Yeah ... they're proliferating. You can't play Whac-A-Mole with this.
Yeah. How do you make something that's just generic no matter what agent you're using? Sure.
And yeah, we're seeing Nemo Claw, and just, I think yesterday or the day before, Microsoft announced this thing, Scout. Yeah. Which Scout is another OpenClaw wrapper, essentially, just their thing around it.
So yeah, they're definitely proliferating. We take a two-stage approach. The first stage, which actually goes back to what you said of turn things on one at a time, is we put protection in front of the organization's critical resources.
And we use this word resources a lot. That can be a database, it can be a SaaS in the cloud, it can be a piece of a manufacturing line, it can be a whole bunch of different kind of resources. But those resources, we stick zero trust controls in front of those, and they won't let the AI get at those resources unless it's been properly onboarded, it's surrounded by appropriate controls, it's entitled to do what it's trying to do, and so on and so forth.
So at least you know at that level that the AI can't destroy your entire company by wiping out your customer database or your code or whatever else is important. These horror stories we hear. Yeah, whatever else is important to you.
So that's step one. Step two is what we call the sentry, with an S, and the sentry is really an encapsulation of each agent, and the agents have a lot of commonality in how they work, and we watch each agent's actions locally where it is. So the first step, protecting the resources, is great, but even just acting locally on your laptop, maybe you've got a confidential file on your laptop.
There's no resource that's going to be protected there, but the agent could still abuse that local file. So we do put these controls around completely encapsulating the agent. So essentially, every action that it takes, whether it's reading a file or sending an email or whatever else it might be doing locally on your machine, we place controls there, and we monitor it.
Some things can be black and white. Maybe you say the agent's not allowed to write a script locally and execute it. That's just a black-and-white thing.
Other things might be more a question of judgment. So we might say the agent's not allowed to ask for a violent image from the internet. Then it's due to the interpretation of how did they ask, what is a violent image, and so on.
That's a tough one to enforce. Yeah. That's what- So you can't have perfect enforcement on that, but you can still have this 95% protection against those bad intents.
Sure. So those two things put together, really, when we talk about zero trust for AI, those two components are really the key parts in delivering. Agreed.
There was also an NVIDIA partnership here, yeah? Yeah, definitely. Everybody wants to partner with NVIDIA.
It's Pax NVIDIA we live in, I feel like now. But tell me about the NVIDIA partnership. Sure.
So we've been working with them for a while. Our kind of natural kind of customer sets are large enterprises, large government organizations, and so on. So historically, prior to the last 12 months, we hadn't been so involved in kind of the data center world and the data center build-out.
Otherwise, there's really only a handful of companies, the Googles and whomever, who are sophisticated enough to really do it for themselves. So Xage is really building this security scaffolding, which just as you said in your own company, it's the underpinning that allows people to start to use AI for the things that matter to them. And so, of course, thank God, Nvidia quite excitedly, we did an initial announcement around the use of AI, specifically in critical infrastructure back in February.
We were one of the five companies that Nvidia used in that announcement, along with a few others you probably have heard of, like Cisco and Siemens and other folks like that. Cisco. Yeah, I've heard that name.
Yeah, exactly. So then- Good for-- Well- ... this sophisticated- Good stuff for you to be in, Duncan ...
yeah, we were definitely the minnow of that particular shoal of fish, but happy to be there. But nonetheless, we've continued to work with them. And in fact, the announcement earlier this week with Nvidia was triggered directly off this zero trust for AI announcement that we did ourselves last week.
" And they selected, I think it was a little bit more than five, about a dozen, Cisco's on the list once again, actually. About a dozen launch partners for that AI factory. And they added Xage to that list, and we got to be called out in Jensen's presentation at GTC at the beginning of the week.
When he was doing that and we kind of did our own thing. But really what that is doing is we have built our zero trust protection deep inside the Nvidia technology stack and integrated it very tightly. And because of the very powerful silicon that they have, we're able to do that at absolutely enormous scale.
So- Yeah ... with a single- And that is- Yeah ... scale, AI scale- Yeah ...
as we're calling it. That's an important piece to this whole thing. " Yeah.
But when Alan has 100 agents, and there's 100 Alans. Yeah. Exactly.
It's a different thing. So the stuff that we've demonstrated this week, it can control about 50 million agents in an AI factory in one go. We're about- That's scale.
Right. So about 10 million simultaneous AI interactions, we think. We haven't actually managed to test it that far, but from the modeling we've done, we think that's how far it will go.
And of course, you can scale horizontally and have multiple of them, too. But really, it comes down to when you have that many agents and LLMs and data all interacting with each other, you have to automate the control fully. " Maybe for one or two very sensitive things, you can have human in the loop, but most of it has to be fully automated control.
And that's what the Nvidia announcement is really about building. Excellent. You know what I realized we didn't, I'm just looking at notes over here, Duncan.
Yeah. Go for it. We never even mentioned the website, did we?
Yeah. com. And I'll tell you the reason for the name, not that you're asking, but the X of Xage is supposed to represent the different things talking to each other.
So again, this idea of many things talking to many things, which is just philosophizing now in the AI world. That was the idea that we were aiming for when we started- That was behind it ... the company.
Yeah. I love it. Well, listen, man, I wish you the best of luck.
Thank you for coming on here today. We'll check back in a few months because the way this agentic AI thing is going- Yeah ... by September, who knows?
We'll talk. Exactly. Everything's accelerating all the time, so it's super fun.
And thanks for the great questions- It's glory time ... and appreciate it. All right.
com. That's X-A-G-E. Zero trust agentic AI security and Nvidia partner.
We're going to take a break on Techstrong. We'll be back in a minute.